CVE-2026-92254: WatchDog Antivirus kernel driver arbitrary file deletion via unauthenticated IOCTL
Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary files with SYSTEM privileges, bypassing NTFS access controls and potentially disabling security products or destabilizing the operating system, via crafted IOCTL requests sent to the \Device\wsdk device.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchDog Antivirus (wsdkd.sys kernel driver)to a version that resolves this vulnerability.Fixed in 1.8.640
Event History
Frequently Asked Questions
Who can exploit this issue?
A local attacker with low privileges on an affected Windows system can exploit it. The attacker must be able to send crafted IOCTL requests to the \Device\wsdk device.
What is the impact of successful exploitation?
An attacker can delete arbitrary files with SYSTEM privileges, bypassing NTFS access controls. This could disable security products or destabilize the operating system.
Which versions are affected?
The issue affects WatchDog Antivirus 1.8.640 where the wsdkd.sys driver is version 1.3.0.0 or earlier.